cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
247
Views
0
Helpful
1
Replies

VPN timeouts and multiple connections

aacquanit
Level 1
Level 1

Before setting 'timeout conn 8:00:00' from I think 10min the vpn client would timeout often. Now that's pretty good the client tunnel stays open.

Since then I've also added 'isakmp keepalive 10' to the pix and 'ForceKeepalives=1' in the client config. So I'm wondering if I can put the timeout conn back down?

Last question... If I connect to the vpn from my windows machine, loggof that, and then connect from another machine behind the same ip with the same id and pw I get to login, I get the same IP the windows machine had but I can't ping or connect to anything for about 10 to 20 min's. The pix logs all have '%PIX-6-106015: Deny TCP (no connection)' and then that stops and the connection works... any ideas on that one?

1 Reply 1

umedryk
Level 5
Level 5

The error message is logged when the PIX Firewall discards a TCP packet that has no associated connection in the PIX Firewall unit's connection table. PIX Firewall looks for a SYN flag in the packet, which indicates a request to establish a new connection. If the SYN flag is not set, and there is not an existing connection, the PIX Firewall discards the packet.